Connect with us

Tech

Nvidia’s game-changing RTX Spark laptops are coming in October – but price information is still MIA

Published

on

At IFA 2026, the huge tech show in Berlin, Germany, Nvidia announced that laptops running on its ARM-based RTX Spark chip will be available to buy from October.

The biggest names in the laptop industry, including Microsoft, Lenovo, HP, and Dell, will all have RTX Spark devices, and I got to spend a bit more time with some of them at Nvidia’s launch event.

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

MartinLogan Motion Discrete Cinema Series Targets Big-Screen Home Theaters With Premium LCR Speakers and Passive Soundbars

Published

on

Televisions have become substantially larger over the past decade, but the audio systems sitting beneath them have not always kept pace.

Mount an 85-inch television on the wall and place a compact soundbar underneath it and the mismatch can be rather obvious. There are certainly active soundbars capable of producing impressive output, but buyers who want a genuine left, center and right front soundstage usually have to choose between three conventional loudspeakers, architectural speakers hidden in the wall, or a premium passive soundbar.

MartinLogan thinks there is another way.

The new Motion Discrete Cinema Series consists of six passive loudspeakers designed specifically around 65, 75 and 85-inch class televisions. Three are individual LCR speakers that can be installed vertically or horizontally, while three combine discrete left, center and right channels inside a single enclosure.

Advertisement

More interestingly, MartinLogan has not simply made the cabinets longer as the screen size increases. The company increases the number of drivers as well, with the goal of increasing output capability and acoustic scale along with the size of the display.

That makes this considerably more interesting than another skinny speaker designed primarily to disappear beneath a television.

Two Ways to Build the Front Soundstage

The Motion Discrete Cinema lineup is divided into LCR5, LCR7 and LCR9 loudspeakers, plus Soundbar 65, Soundbar 75 and Soundbar 85 three-channel passive soundbars.

All six models use MartinLogan’s Gen2 Folded Motion Tweeter with Folded Motion Waveguide, woven fiberglass woofers and extruded aluminum enclosures.

Advertisement
martinlogan-motion-discrete-cinema-lcr-speakers

The LCR5 is designed as a height match for 65-inch class displays and uses a five-driver array consisting of the Gen2 Folded Motion Tweeter and four 4.5-inch woven fiberglass woofers.

The LCR7, intended for 75-inch displays, adds two additional woofers for greater output, higher power handling and improved room control in larger spaces. The flagship LCR9 moves to a nine-driver configuration designed to provide greater output and scale alongside an 85-inch display.

All three can function as left, center or right speakers, which means an installer could place three vertically around a display, rotate one horizontally beneath the television for center-channel duty, or use them as high-output surrounds where their shallow profile makes sense.

Advertisement. Scroll to continue reading.
Advertisement

The Soundbar models take a different approach.

These are not powered soundbars competing directly with products like the Sonos Arc Ultra. There is no built-in AVR replacement here. The Soundbar 65, 75 and 85 contain discrete left, center and right loudspeaker channels and require external amplification.

That means an AV receiver or separates still handle decoding, amplification, bass management and the rest of the home theater system. The advantage is that buyers get three physical front channels inside one enclosure without surrounding a large television with three conventional speaker cabinets.

The Soundbar 65 is designed for 65-inch class displays and uses a Gen2 Folded Motion Tweeter and two woofers per channel. The Soundbar 75 increases the driver count, including twice as many woofers in the center channel and additional drivers for the left and right channels.

Advertisement

At the top of the range, the Soundbar 85 uses a 15-driver array across its three discrete channels.

martinlogan-motion-discrete-cinema-speaker-no-grille

What Makes Motion Discrete Cinema Different?

Screen matching is the clever part.

Plenty of manufacturers produce passive soundbars and slim on-wall loudspeakers. MartinLogan’s approach is to create three progressively larger configurations and increase their acoustic capability rather than offer essentially the same speaker in different cabinet lengths.

That becomes especially relevant with today’s 75 and 85-inch televisions, where a small center channel or narrow soundbar can look disproportionately small and may struggle to create the sense of scale expected from a large image.

Advertisement

There is also some real loudspeaker technology inside these enclosures.

MartinLogan has managed to incorporate its full-size Gen2 Folded Motion Tweeter and an application-optimized Folded Motion Waveguide rather than developing a miniature tweeter specifically to squeeze into the cabinet. The woofer system was intentionally optimized around midrange and upper-bass performance, with MartinLogan assuming that a serious home theater installation will include at least one powered subwoofer.

That last point is worth remembering. These are not being positioned as full-range loudspeakers that somehow violate several inconvenient laws of physics simply because they are expensive and made from aluminum.

Use a subwoofer.

Advertisement
Advertisement. Scroll to continue reading.

Preferably a good one made by MartinLogan.

Where Do They Fit in the MartinLogan Lineup?

The Motion Discrete Cinema Series fills a fairly obvious hole between MartinLogan’s existing Motion SLM products and its larger conventional Motion and Motion XT loudspeakers.

The Motion SLM family already gives MartinLogan customers thin on-wall speakers designed to complement flat-panel televisions, including individual SLM models and the three-channel Motion SLM X3.

Advertisement

Motion Discrete Cinema is a considerably more ambitious interpretation of the same basic installation problem.

It incorporates MartinLogan’s newer Gen2 Folded Motion technology, offers substantially larger driver arrays and gives installers dedicated versions intended to complement 65, 75 and 85-inch displays.

The new series also overlaps the price territory of MartinLogan’s conventional Motion center-channel speakers, but that does not necessarily make Motion Discrete Cinema a higher-performance tier than Motion XT.

They are built for different jobs.

Advertisement

Motion XT remains MartinLogan’s premium conventional Motion range, including larger cabinets and the company’s Gen2 Folded Motion XT tweeter. Motion Discrete Cinema instead gives custom installers a premium shallow-depth alternative when conventional loudspeaker cabinets would interfere with the room design or television installation.

In other words, you’re paying partly for acoustics and partly for solving a very specific installation problem without reducing the front stage to a typical powered soundbar.

Designed for Custom Installation

The CI focus becomes even clearer when looking at the mounting hardware.

Every Motion Discrete Cinema model includes a universal wall bracket offering leveling and small positional adjustments, useful when wall studs refuse to cooperate with the architect’s carefully centered television.

Advertisement

An optional television bracket can attach to a display frame or VESA mounting pattern, allowing the loudspeaker to move with an articulating television.

Advertisement. Scroll to continue reading.

MartinLogan has also integrated recessed cable channels into the aluminum chassis to conceal wiring, while removable Phoenix-style connectors with tool-free tension levers allow installers to terminate the speaker cable before the loudspeaker itself is mounted.

None of that will make anyone abandon dinner to stare at the specifications page, but installers will notice immediately. The difference between a clever mounting system and three hours of profanity behind an 85-inch television is not insignificant.

Advertisement
martinlogan-motion-discrete-cinema-soundbar

What Are the Closest Competitors?

The closest competition depends on which Motion Discrete Cinema configuration you are considering.

For the individual LCR speakers, the Focal On Wall 302 is arguably the most direct rival. At roughly the same price as the LCR9, it is another premium low-profile loudspeaker intended for home theater installations where conventional speaker cabinets are undesirable. It can also be mounted vertically or horizontally and uses four Flax midbass drivers surrounding Focal’s inverted-dome tweeter.

That makes it a credible alternative for someone building a premium low-profile LCR system around a large television.

For the three-channel models, the GoldenEar SuperCinema 3D Array XL is one of the most obvious competitors. It occupies similar pricing territory to the Soundbar 65 and also combines three passive front channels within a slim enclosure.

Advertisement

GoldenEar takes a somewhat different technical approach, using multiple midbass drivers, its High-Velocity Folded Ribbon tweeters and proprietary technology intended to create a soundstage wider than the enclosure itself.

MartinLogan’s advantage is the breadth of the new lineup.

Instead of offering one primary passive soundbar configuration, Motion Discrete Cinema provides dedicated 65, 75 and 85-inch models along with corresponding individual LCR speakers.

That gives integrators substantially more freedom to maintain a consistent visual and acoustic design across different rooms and screen sizes.

Advertisement

Pricing & Availability

MartinLogan expects the Motion Discrete Cinema Series to reach authorized dealers and custom integrators worldwide by the end of September 2026.

Motion Discrete Cinema LCR Speakers

  • LCR5: $1,249.99 each
  • LCR7: $1,499.99 each
  • LCR9: $1,749.99 each

Motion Discrete Cinema Passive Soundbars

  • Soundbar 65: $1,999.99
  • Soundbar 75: $2,499.99
  • Soundbar 85: $2,999.99

The Bottom Line

MartinLogan is not trying to reinvent the powered soundbar. Motion Discrete Cinema is aimed at customers who want the cleaner appearance of one without surrendering a properly amplified, discrete home theater system.

Advertisement. Scroll to continue reading.

The ability to choose between separate LCR speakers and three-channel passive soundbars is useful, but the more unusual idea is scaling the driver array with the television itself. An 85-inch display gets a substantially different loudspeaker than a 65-inch model rather than the same acoustic platform wearing a longer grille.

That should make the series especially relevant to custom installers trying to reconcile increasingly enormous televisions with homeowners who have absolutely no interest in seeing enormous loudspeakers sitting beside them.

Advertisement

Physics still gets a vote, however, which is why MartinLogan wisely expects owners to add a subwoofer.

Some things even a very expensive piece of aluminum can’t negotiate.

Source link

Advertisement
Continue Reading

Tech

The Very Real Dangers Of Using Hotel Wi-Fi

Published

on





Access to Wi-Fi is something you expect when you stay at any hotel, but we’re so accustomed to taking this amenity for granted that we might overlook the risks involved in connecting to hotel Wi-Fi. Ignoring the fact that people pick up their phones a worryingly excessive number of times each day, there are multiple reasons to avoid using hotel Wi-Fi when you can.

These risks can come in several forms. First, when connecting to a network, you must ensure the one you’re connecting to is legitimately operated by the hotel you’re staying at. Hackers attempting to steal user data can create hotspots with misleading network names, and accidentally connecting to the wrong network could be playing into the hands of cybercriminals. At least one security analyst says a relatively common error travelers make involves joining a network merely because it includes the name of the hotel.

Unfortunately, even if you do connect to an authentic hotel Wi-Fi network, you still can’t be certain your data is secure. Real-world examples serve as reminders of this. For instance, Darkhotel was a malware campaign in which hackers infected the computers of various hotels with code designed to provide guest users with fake software updates, turning guests into data theft victims.

Advertisement

And those are just a couple of scenarios. Although not all security experts agree on just how dangerous hotel Wi-Fi is, even those who think the risk is fairly low still discourage users from connecting to these networks for sensitive tasks, like checking banks accounts.

Advertisement

Tips for guarding against hotel Wi-Fi risks

Confirming the network you’re connecting to is genuinely the hotel’s network is critical before joining it. Experts also recommend using a mobile hotspot instead when handling sensitive tasks. None of the information here is fear-mongering. The FBI actually considers hotel Wi-Fi cyberthreats to be a significant enough issue to justify warning the public about it. In an age when telecommuting is increasingly common, the FBI has determined that more and more Americans are working from hotels. In response to this trend, the FBI issued recommendations to help users maximize safety and security if they must connect to a hotel’s Wi-Fi network.

Specifically, the FBI recommends leveraging a VPN to encrypt network traffic, which means researching the best VPN services available right now to find a reputable one that serves your needs. The FBI also states that you can protect yourself and your data to an even greater degree by making sure all software updates are installed and using a strong security or antivirus app to maximize safety. Luckily, there are several free antivirus apps that consumers say are effective, with many antivirus programs proving to be better than Windows Defender.

All that said, if you can avoid using hotel Wi-Fi entirely, that may be your best option. While experts offer varying perspectives on just how dangerous using one of these networks is, when you have the choice to limit your vulnerability, you should protect yourself accordingly. If you do have to use hotel Wi-Fi, however, just make sure you’re thoroughly following safety recommendations.

Advertisement



Source link

Continue Reading

Tech

Microsoft AI’s MAI-Transcribe-2 undercuts OpenAI, Google and ElevenLabs on price and speed

Published

on

Microsoft AI on Thursday released MAI-Transcribe-2, a speech-recognition model the company says is faster, more accurate, and cheaper than anything OpenAI, Google, or ElevenLabs currently sells. Then it priced the thing at 10 cents per hour of audio.

That figure deserves a pause. When Microsoft AI shipped the first model in this line just five months ago, it charged $0.36 an hour. Thursday’s early-bird price cuts that by roughly 72%. For an enterprise processing 100,000 hours of call-center audio a year — a modest volume for a large bank or telecom — the bill drops from $36,000 to $10,000. At that level, transcription stops being a line item anyone argues about.

The release arrives as Microsoft executes a strategy that would have seemed implausible two years ago: building its own frontier-class models one modality at a time, then steadily swapping them into products that once ran on OpenAI’s technology. Transcription is the modality where that plan has moved fastest, and MAI-Transcribe-2 is its clearest proof point yet. It also offers a preview of how the world’s most valuable software company intends to compete in AI without depending on the partner it spent $13 billion to cultivate.

What MAI-Transcribe-2 does and why the feature list matters to enterprise buyers

The model transcribes audio in 60 languages, up from 43 in June’s MAI-Transcribe-1.5 and 25 in April’s original release. It runs on Microsoft Foundry, the company’s model marketplace for developers, and in MAI Playground, its testing environment. Microsoft says it built the model for the messy audio that real businesses generate — background noise, low-quality recordings, overlapping speech — rather than clean studio conditions.

Advertisement

More important than the language count is what Microsoft has bundled into the base product. Speaker diarization sorts out who said what in a multi-person recording, which is the difference between a wall of text and a usable meeting transcript. Word-level timestamps attach a precise time marker to every word, enabling search, editing, and alignment with video. Keyword biasing lets developers feed the model a list of drug names, product codes, or employee names so it stops mangling domain jargon. Automatic language identification means users no longer have to declare the language in advance.

Two features stand out for their specificity. A configurable output style offers a “verbatim” mode that preserves every “um,” false start, and stutter for compliance and legal teams, alongside a “clean” mode that strips fillers for readable captions and notes. And code switching handles conversations that drift between languages mid-sentence; Microsoft explicitly names Hinglish and Spanglish, a nod to the Indian and U.S. Hispanic markets where a single customer-service call might toggle languages a dozen times. Specialty vendors have historically charged premiums for each of these capabilities. Microsoft is including all of them for a dime.

How to read Microsoft’s FLEURS and Artificial Analysis benchmark claims

Microsoft makes three performance claims, each resting on a different measuring stick, and technical buyers should understand what each one captures and what it misses.

The first is that MAI-Transcribe-2 ranks number one on FLEURS across 60 languages with an average word error rate of 5.2%. FLEURS is a benchmark Google researchers published in 2022, built from native speakers reading roughly 2,000 sentences in each of 102 languages — about 12 hours of speech per language. It is the standard yardstick for multilingual speech recognition because it lets you compare a model’s Swahili against its Swedish on identical content. Word error rate, its metric, simply counts substitutions, insertions, and deletions against a human reference; 5.2% means roughly one word in 20 is wrong. But FLEURS is read speech, not conversation, and Microsoft’s average has actually risen from the 3.7% it reported for MAI-Transcribe-1.5 in June. That almost certainly reflects broader coverage rather than regression — averaging across 60 languages instead of 43 means folding in low-resource languages where every model struggles — but buyers should request the per-language breakdown.

Advertisement

The second claim is that the model ranks second on the Artificial Analysis word-error-rate leaderboard and defines that firm’s accuracy-latency Pareto frontier. Artificial Analysis is an independent benchmarker that tests models through their public APIs, measuring what a customer actually gets. Its index blends simulated agent conversations, European Parliament speeches, and corporate earnings calls, weighting heavily toward English business speech. In June, the firm ranked MAI-Transcribe-1.5 third at 2.4% WER, behind Alibaba’s Fun-Realtime-ASR-preview and ElevenLabs’ Scribe v2, while calling it the fastest model in the top 10. Climbing to second suggests Microsoft has cleared ElevenLabs. “Pareto frontier” is the phrase practitioners should note: it means no rival beats the model on accuracy without being slower, and none beats it on speed without being less accurate.

The third claim is raw speed — 10 times faster than OpenAI’s GPT-Transcribe, seven times faster than ElevenLabs’ Scribe v2, five times faster than Google’s Gemini 3.5 Transcribe, per Artificial Analysis evaluations. In batch transcription, speed matters less because anyone is waiting and more because throughput is cost. A model running at 300 times real-time needs a fraction of the GPU-hours of one running at 30 times. That efficiency is what lets Microsoft charge a dime and, presumably, still make money.

Three speech models in five months: inside Microsoft AI’s rapid release cadence

The pace is the story within the story. On April 2, MAI-Transcribe-1 launched with 25 languages at $0.36 per hour. On June 2, MAI-Transcribe-1.5 arrived with 43 languages, keyword biasing, and a third-place ranking on Artificial Analysis. Today, MAI-Transcribe-2 shipped with 60 languages, diarization, timestamps, code switching, a second-place ranking, and a price of $0.10.

Three releases in five months, each expanding language coverage by roughly 40% while adding features competitors gate behind premium tiers. That cadence is characteristic of a team that has settled on a stable architecture and is now turning the crank on data and scale — the phase where speech models tend to improve quickly and predictably. It is also the cadence of a company that intends to make transcription a commodity before anyone else can.

Advertisement

The organizational bet behind that speed is one Mustafa Suleyman, Microsoft AI’s chief executive, described to The Verge in April. He credited the first model to “a small, focused 10-person team” that had been “liberated from any of the bureaucracy,” with a larger surrounding group handling vendor management and data acquisition.

He also told The Verge the model ran at “half the GPU cost of the other state-of-the-art models,” calling it “a huge cost-saving” for Microsoft. Meta, Amazon, Google, and Anthropic have all experimented with similar flattened structures, The Verge noted. Microsoft’s transcription line is the most visible test yet of whether the approach produces commercial results rather than research papers.

Why Microsoft is building its own AI models despite its $13 billion OpenAI bet

Microsoft has invested more than $13 billion in OpenAI, and hosts OpenAI’s models across Azure, Office, and Copilot. For most of the past four years, the obvious question about any Microsoft-built model has been: why bother? The answer has sharpened over the past year, and it begins with independence.

When Microsoft hired Suleyman from Inflection AI in March 2024, along with most of Inflection’s staff, Salesforce CEO Marc Benioff read it as a declaration of intent. “Microsoft is building their own AI and I don’t think Microsoft will use OpenAI in the future. They’ll have their own frontier models,” Benioff told CNBC in January 2025. “That’s why they hired Mustafa Suleyman.” Benioff had his own motives — Salesforce competes with Microsoft and invests in Anthropic — but events have largely borne him out.

Advertisement

In October 2025, Microsoft and OpenAI restructured their partnership in a deal that, per Microsoft’s own announcement, allowed Microsoft to “independently pursue AGI alone or in partnership with third parties” for the first time. Suleyman told The Verge that renegotiation “unlocked [Microsoft’s] ability to pursue superintelligence,” and Microsoft announced its MAI Superintelligence team weeks later. In April 2026, the companies amended the deal again, ending Microsoft’s exclusive access to OpenAI’s models and eliminating Microsoft’s revenue-share payments, according to reports at the time. Each amendment loosened the tie. Each one was followed by more MAI models.

How Microsoft’s in-house models are cutting costs across Teams, Word, and Excel

The second half of the answer is margin. Every prompt Microsoft routes to an OpenAI model carries a cost. Every prompt it routes to its own model on its own GPUs carries a smaller one. In July, Bloomberg reported that Microsoft had begun using MAI models to answer a portion of user prompts in Word and Excel — products it had previously advertised as powered by OpenAI and Anthropic. TechCrunch framed the shift as part of a broader industry pullback on AI spending, with Amazon, Uber, Meta, and Accenture all reportedly trimming.

Transcription is the natural first target for this substitution because the problem is bounded and the metric is objective. Microsoft owns Teams, which generates an enormous volume of meeting audio. It owns Nuance, whose clinical documentation business runs on speech recognition. It owns the Azure speech services that thousands of enterprises already call. Every one of those workloads is a candidate to move onto MAI-Transcribe-2, and every hour that moves is an hour Microsoft no longer pays anyone else for.

Suleyman has been unusually candid that this is the point. Superintelligence, he told The Verge in April, “is really about, ‘Are these models capable of delivering product value for the millions of enterprises that depend on us to deliver world-class language models?’” Whatever one thinks of applying the word “superintelligence” to a transcription API, the commercial logic is plain: build the capability once, deploy it across a dozen products, and stop writing checks to a partner that is increasingly a competitor.

Advertisement

MAI-Transcribe-2 vs. OpenAI, Google, and ElevenLabs: the competitive picture

Microsoft’s release names four rivals: OpenAI’s GPT-Transcribe, Google’s Gemini 3.5 Transcribe, OpenAI’s older Whisper V3-Large, and ElevenLabs’ Scribe v2. It does not mention Deepgram, AssemblyAI, Speechmatics, or Rev — the specialists that have sold transcription to enterprises for a decade. Microsoft is positioning against the frontier labs, not the incumbents.

That framing is partly marketing and partly true. The frontier labs have treated speech as a checkbox feature of broader platforms, priced accordingly, and a dedicated model that beats them on speed by five to 10 times while matching their accuracy is a genuine differentiator. But the specialists will feel the price pressure most acutely. At $0.10 an hour, Microsoft is pricing at or below where many of them sell high-volume enterprise contracts, and it is bundling diarization, timestamps, and 60 languages into the base rate. The specialists’ remaining moat is domain depth — medical vocabularies, legal formatting, industry-specific integrations — and Microsoft’s keyword biasing feature is aimed squarely at it.

The one competitor Microsoft conspicuously does not claim to beat on accuracy is Alibaba, whose models have posted leading numbers on independent leaderboards for much of 2026. TechCrunch reported in July that some U.S. companies had begun evaluating Chinese models as cheaper alternatives despite security concerns. Microsoft’s pitch to those buyers is implicit but unmistakable: comparable accuracy, faster inference, lower price, and a vendor your compliance team already trusts.

The questions technical decision makers should ask before switching transcription vendors

For all its specificity on benchmarks, the release leaves several practical questions open. The first is duration: Microsoft calls $0.10 per hour a launch offer without naming an end date or a standard rate, and anyone building a cost model should get both in writing. The second is streaming. The release emphasizes batch throughput and long-form audio but says nothing about real-time transcription, which voice agents and live captioning require. Artificial Analysis maintains a separate streaming leaderboard, and Microsoft’s silence on it is notable.

Advertisement

The third is per-language accuracy. A 5.2% average across 60 languages could mean 3% on major languages and 12% on low-resource ones, so buyers with specific needs should test those languages directly. The fourth is diarization quality. Word error rate does not measure speaker attribution; a transcript can have near-perfect WER and still assign every other sentence to the wrong person. The release offers no diarization error rate or comparable metric.

The fifth is data handling. Enterprise transcription touches medical records, legal privilege, and financial disclosures, and the release says nothing about data residency, retention, or whether audio submitted to Foundry feeds future training. Microsoft’s April announcements described training data as a mix of human-curated recordings, contractor-recorded noisy audio, and “vast amounts of data from the open web,” per The Verge — a description that should prompt pointed questions from regulated industries. None of these gaps is unusual for a launch announcement, but they are exactly the questions that separate a leaderboard win from a production deployment.

What Microsoft’s speech model strategy reveals about its broader AI ambitions

Step back from the speech-recognition details and a pattern emerges that extends well beyond transcription. Microsoft’s AI unit now ships models for images, voice, transcription, code, reasoning, and cybersecurity. At Build in June, it announced seven new MAI models in a singlekeynote. Each follows the same playbook: target a well-defined modality, optimize aggressively for inference cost, price below the frontier labs, distribute through Foundry, and quietly swap the model into Microsoft’s own products.

This is not an attempt to build one model that beats GPT or Gemini at everything. It is an attempt to build a portfolio of specialized models that, in aggregate, let Microsoft serve most of its enterprise workloads without paying anyone else — and to sell the surplus capacity to everyone else at prices the specialists cannot match. Transcription happened to be the first modality where the approach fully matured, but the release notes for MAI-Transcribe-2 read less like a product announcement than a template.

Advertisement

Suleyman has spent two years talking about “humanist superintelligence” and AI assistants that are “accountable to them, on their side.” The vocabulary is lofty. The execution is a spreadsheet. Five months ago, Microsoft charged 36 cents to turn an hour of speech into text. On Thursday it charged a dime, threw in six features its rivals sell separately, and claimed the top spot on the industry’s standard multilingual benchmark. The company that spent $13 billion learning what frontier AI costs has decided it would rather own the factory than rent the output — and now it is selling the output for less than the rent.

MAI-Transcribe-2 is available now through Microsoft Foundry and MAI Playground.

Source link

Advertisement
Continue Reading

Tech

Kaleidescape 246TB Terra Prime SSD Packs 4,000 4K Movies Into One Compact Server

Published

on

How large does a digital movie collection need to become before storage starts getting a little ridiculous?

Kaleidescape apparently thinks 246TB is a reasonable place to find out.

At CEDIA Expo 2026, the company introduced the Compact Terra Prime 246TB SSD Movie Server, its highest-capacity server to date. What makes it more interesting than another exercise in storage excess is the packaging: Kaleidescape has squeezed two 123TB solid-state drives into the same compact chassis used by the Strato K 8K movie player.

For perspective, the full-size Terra Prime 120TB introduced earlier this year suddenly looks rather modest.

Advertisement

The new model is aimed at very large Kaleidescape collections, whole-home installations and marine systems where multiple Strato players need immediate access to a centralized movie library.

And presumably people who regard deleting a downloaded movie as a personal failure. It appears someone at Kaleidescape finally read my email.

How Much Fits on 246TB?

Kaleidescape estimates the Compact Terra Prime can store approximately 4,000 conventional 4K movies, 2,300 4K Cinematic or 8K movies, 6,600 HD movies, or 37,000 SD titles.

There is an important distinction with that 2,300 figure. It represents storage capacity based on typical file sizes; it does not mean Kaleidescape currently offers 2,300 native 8K movies.

Advertisement
kaleidescape-compact-terra-prime-ssd-top-open
Compact Terra Prime 246TB SSD with top open at CEDIA Expo 2026

The company offers more than 14,000 titles across its supported formats, while its newer 4K Cinematic and 8K playback capabilities are tied to the Strato K platform.

Storage requirements are also moving upward. Kaleidescape says 4K Cinematic downloads average approximately 1.5 times the size of its conventional 4K versions, with average bitrates around 110 Mbps. The format can retain chroma information up to 4:4:4 and was introduced alongside Strato K in June 2026.

Strato K itself includes a 960GB SSD, which is useful for a small standalone library but can hold only about seven 4K Cinematic titles. Connecting it to Terra storage removes that constraint and lets the player concentrate on playback while the server maintains the collection.

Advertisement. Scroll to continue reading.
Advertisement

That makes a huge server considerably easier to understand, even if most home theater owners will never come remotely close to needing this much capacity.

kaleidescape-compact-terra-prime-ssd-explode

SSD Changes More Than Storage Capacity

The existing Terra Prime 120TB uses four removable hard drives in a traditional full-width component. Moving to SSDs allows the 246TB version to deliver considerably more capacity in a chassis less than half as wide.

There are also performance advantages.

Compact Terra Prime 246TB SSD Terra Prime 120TB
Storage 246TB 120TB
Storage Type 2 x 123TB SSD 4 x HDD
Approx. 4K Movies 4,000 2,000
4K Download Time As little as 4 minutes As little as 8 minutes
Simultaneous 4K Playbacks 25 10
Network 2.5GbE recommended 2.5GbE recommended
Dimensions 7.87 x 1.52 x 10 inches 17 x 3.5 x 10 inches
Weight 4 pounds 21.6 pounds with drives
Typical Fan Noise 20 dB(A) 29 dB(A)

With a 2.5 Gigabit Ethernet connection, Kaleidescape says a high-bitrate 4K movie can download in as little as four minutes.

Advertisement

The more relevant specification for large custom installations may be simultaneous playback. One server can provide high-bitrate 4K content to as many as 25 network-connected Strato players.

Nobody needs 25 movie zones in a two-bedroom condo.

In a large residence, yacht or other professionally integrated system, that capability starts making considerably more sense.

Almost One Petabyte of Kaleidescape

kaleidescape-compact-terra-prime-ssd-rack-mount-stacked-angle

If 246TB somehow proves inadequate, Kaleidescape allows up to four Compact Terra Prime SSD servers to operate together.

That creates a maximum combined capacity of 984TB, just shy of one petabyte.

Advertisement

Kaleidescape says three of the new servers provide sufficient capacity for its entire current Movie Store based on typical storage requirements.

This is where the intended customer becomes fairly obvious. Someone building a modest single-room Kaleidescape system can choose the Strato E, Strato M, Strato K and considerably smaller Terra options already in the lineup.

kaleidescape-compact-terra-prime-ssd-rack-mount-stacked

The 246TB server exists for installations where users want an enormous collection stored locally and available instantly throughout the property without continually deciding what stays downloaded.

Advertisement. Scroll to continue reading.
Advertisement

Kaleidescape has never been about cloud streaming. Purchased movies are downloaded to local storage and then played directly from the system, which allows the company to use movie files and bitrates that would be impractical for conventional streaming services.

Increasing local storage therefore becomes increasingly useful as Kaleidescape pushes toward higher-quality downloads.

What About Price?

Kaleidescape has not announced a fixed MSRP for the Compact Terra Prime 246TB SSD.

The server is available now on a special-order basis through authorized Kaleidescape dealers.

Advertisement

That is probably just as well.

For context, the Terra Prime 120TB sells for $34,995, before adding a Strato movie player. Two 123TB enterprise-class SSDs are not exactly something you pick up from the impulse aisle at Costco, so attempting to reverse-engineer a retail price from consumer SSD pricing would be pointless.

Anyone genuinely shopping for one will be speaking with an authorized integrator anyway.

Specifications

  • Product: Kaleidescape Compact Terra Prime SSD Movie Server
  • Storage: 246TB
  • Drives: 2 x 123TB SSD
  • Approximate Storage: 2,300 8K or 4K Cinematic movies; 4,000 4K movies; 6,600 HD movies; 37,000 SD movies
  • Download Speed: High-bitrate 4K movie in as little as 4 minutes
  • Simultaneous Playback: Up to 25 network-connected Strato players
  • Networking: 2.5 Gigabit Ethernet recommended; 1 Gigabit minimum
  • USB: USB 3.0, reserved
  • Dimensions: 7.87 x 1.52 x 10 inches
  • Weight: 4 pounds
  • Typical Power Consumption: 22 watts
  • Maximum Power Consumption: 42 watts
  • Typical Fan Noise: 20 dB(A)
  • Construction: Black anodized aluminum
  • Rack Mounting: Optional 1U shelf supports one or two compact units
  • Supported Storage: 8K, 4K Cinematic, 4K Dolby Vision, 4K HDR10, 4K SDR, HD and SD Kaleidescape downloads
  • Availability: Available now by special order through authorized Kaleidescape dealers
kaleidescape-models-2026
Kaleidescape players and servers at CEDIA Expo 2026

The Bottom Line

The Compact Terra Prime 246TB SSD is clearly not intended to make Kaleidescape more affordable. Strato E and Strato M have already taken on that job by lowering the cost of entering the ecosystem.

This product pushes in the other direction.

Advertisement

Kaleidescape is building an increasingly scalable platform in which a relatively simple single-room system can coexist with installations serving dozens of playback zones and enormous locally stored collections. Strato K and 4K Cinematic have also increased the amount of data required to deliver the company’s best video quality, making higher-capacity storage more than just a game of spec-sheet one-upmanship.

Does anyone really need almost a quarter-petabyte of movie storage in one box?

Probably not many people.

Advertisement. Scroll to continue reading.
Advertisement

But the customers who do were unlikely to be satisfied with 120TB anyway.

For more information: kaleidescape.com

Source link

Advertisement
Continue Reading

Tech

Microsoft warns fake CAPTCHA is tricking Windows users into running malware

Published

on

The takeaway: Microsoft has identified a new malware campaign that uses fake CAPTCHA prompts to trick Windows users into running malicious commands. The campaign, called TerminalFix, is a variation of the ClickFix attacks that have become increasingly common among business users. The campaign highlights a broader security problem: familiar browser prompts can now bypass technical safeguards by convincing users to execute the attacker’s code themselves.

The pages impersonate Cloudflare and other trusted services. Instead of presenting a normal CAPTCHA challenge, they instruct users to open PowerShell or Command Prompt and paste in a command.

That is the main difference between TerminalFix and earlier ClickFix activity. ClickFix attacks often direct victims to the Windows Run dialog, where a command is used to install an information stealer. TerminalFix, by contrast, uses PowerShell or Command Prompt, making it easier for attackers to execute longer, multi-line scripts.

Microsoft said the change increases “the likelihood that complex, multi-line scripts execute successfully.”

Advertisement

The campaign is designed to do more than infect a single computer. After a user runs the command, TerminalFix can begin a multi-stage intrusion that gives the attacker persistent proxy access through the compromised machine. That access can provide a route into other parts of a company’s network.

An attacker with access to an unsecured network could use the initially infected system to steal data, spread malware to other devices, or install ransomware. The extent of the damage would depend on the victim’s network controls, endpoint security, and user permissions.

TerminalFix relies on social engineering rather than a hidden software exploit. The attacker needs the user to follow the instructions on the fake verification page, making employee awareness an important line of defense.

A CAPTCHA that asks someone to open PowerShell, Command Prompt, or the Windows Run dialog should be treated as suspicious. Legitimate CAPTCHA services do not require users to run system commands to prove they are human.

Advertisement

Microsoft Threat Intelligence has published mitigation guidance for organizations. The company recommends restricting access to PowerShell and the Windows Run dialog when possible, monitoring systems for signs of DLL sideloading, blocking Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus.

Those controls may not be appropriate for every employee or device. IT administrators, developers, and other technical users may need access to scripting tools as part of their jobs. Companies can still reduce risk by limiting those tools to users who need them and monitoring for unusual command activity.

Security teams should also review which older software remains installed across their environments. Microsoft’s guidance to block Flash plugins, for example, shows how outdated components can create additional paths for attackers even when they are no longer needed for daily work.

The campaign is primarily a concern for enterprise networks, where one compromised device can provide a path to more valuable systems and data. But the basic advice applies to individual users as well. Do not run a PowerShell or Command Prompt command simply because a website asks you to, especially when the request is presented as a CAPTCHA or security check.

Advertisement

Source link

Continue Reading

Tech

VPN deal of the week: Save $30 with Windscribe’s back-to-school discount

Published

on

Windscribe has reduced its annual plan from $69 to $39 upfront ($3.25/month), just in time for the new academic year.

The plan includes unlimited simultaneous connections — a feature missing from competitors like NordVPN or Proton — along with a built-in ad, tracker, and malware blocker.

Its user-friendly apps are available across desktop, mobile, and many smart TVs, so it can cover everything you need: whether you’re securing public Wi-Fi in the library or streaming back in the dorm.

Crucially, this isn’t a first-year teaser rate. You’ll be billed $39 every 12 months for as long as you keep the subscription active, avoiding the steep renewal price hikes standard across the VPN industry.

Advertisement

Few premium VPNs match this pricing, particularly when accounting for renewal costs. For example, NordVPN‘s one-year plans start at $65.88, over $20 more, and renew at $139 per year. It’s a similar story when you look at the likes of Surfshark and ExpressVPN, too.

It’s also among the fastest VPNs we reviewed during our most recent tests, achieving over 2,000 Mbps over WireGuard. Plus, it reliably unblocks major streaming platforms and bypasses regional internet blocks.

If you’re not keen on Windscribe but want to keep top speeds, PrivadoVPN is another top choice that achieved over 2000 Mbps in testing. Equally, for streaming performance, no VPN performed better than NordVPN with global services this time around.

Advertisement

If you want to test it first, Windscribe offers a solid free tier. While bandwidth and server locations are capped, it gives you a risk-free way to test the interface before upgrading.

Source link

Continue Reading

Tech

Daily Deal: The Adobe Graphic Design Bundle

Published

on

from the good-deals-on-cool-stuff dept

The Adobe Graphic Design Bundle has 3 courses designed to help you learn the essentials of graphic design and how to apply those skills to your projects. Courses cover Photoshop, Illustrator, and InDesign. You’ll learn all aspects of the design process. It’s on sale for $50.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

Filed Under: daily deal

Source link

Advertisement
Continue Reading

Tech

Whistleblower: USPS Defied A Court Injunction To Build An Untested, Undocumented Ballot-Blocking System. Its Own Staff Call The Process “A Shit Show.”

Published

on

from the when-you-it-it-that-way,-it-seems-bad dept

Even as Donald Trump regularly uses mail-in ballots himself, he has decided that mail-in ballots are a system by which voting fraud occurs. To be quite clear, this is bullshit. There is astoundingly little evidence of significant voter fraud, and that’s equally true between in-person and voting-by-mail. And there’s zero evidence that mail-in voter fraud has ever even come close to swinging a federal election. Indeed, what little voter fraud there is often involves mixups of people who thought they were eligible to vote accidentally trying to vote when they were ineligible.

Either way, a few years back, Trump started blaming mail-in ballots for the completely mythological “rigged elections” he keeps insisting are happening, and of course the MAGA establishment quickly fell into line. We just recently wrote about how the Fifth Circuit appeals court has been working overtime to pretend that it’s well-established that mail-in ballots are insecure. But the bigger issue is that earlier this year, Trump issued an executive order to try to limit the use of mail-in ballots.

Specifically, the executive order tells the US Postal Service to engage in a “rulemaking” that is designed to make it much more difficult for states to offer mail-in ballots. And, on top of that, it demands that states that offer mail-in ballots must hand over their voter rolls to the federal government. The White House has been demanding voter rolls from a bunch of states, and so far every state that has engaged in litigation over this issue has won (it’s now over 20 cases, all of which have gone against the administration).

On its face, the executive order should be seen as pure nonsense, given that the states get to run elections, not the federal government. And even if it were the federal government, that’s not what executive orders are for. But given that the same Supreme Court that insisted no Democratic president could do literally anything without explicit congressional approval now treats Donald Trump as the very special birthday boy who gets whatever he asks for, we have to take even his most ridiculous demands seriously.

Advertisement

A district court judge, Indira Talwani, who is overseeing two of the cases challenging that executive order has issued injunctions in both cases, blocking the US government from putting it into effect. As Talwani notes, the states get to determine how their elections are run, per the Constitution.

Article I of the Constitution also empowers the States to prescribe the “Times, Places, and Manner of holding” congressional elections. U.S. CONST. art. I, § 4, cl. 1. “[T]hese comprehensive words embrace authority to provide a complete code for congressional elections, not only as to times and places, but in relation to notices, registration, supervision of voting, protection of voters, prevention of fraud and corrupt practices, counting of votes” among other issues. Smiley v. Holm, 285 U.S. 355, 366 (1932).

The President is elected by vote of the Electoral College. See U.S. CONST. amend. XII. The Electors Clause empowers each State to appoint electors to the Electoral College “in such Manner as the Legislature thereof may direct.” U.S. CONST. art. II, § 1, cl. 2. The States require their electors be appointed by popular vote of qualified voters. See Chiafalo v. Washington, 591 U.S. 578, 584 (2020). Accordingly, the States alone determine voter-eligibility requirements, subject only to the outer limits of the Constitution. See, e.g., U.S. CONST. amend. XIX (“The right of citizens of the United States to vote shall not be denied or abridged . . . on account of sex.”); U.S. CONST. amend. XXVI (“The right of citizens of the United States, who are eighteen years of age or older, to vote, shall not be denied or abridged . . . on account of age.”). For presidential elections, the Electors Clause gives States the primary authority to decide how electors are chosen.

As a result, the court ordered (among other things) the USPS to not take any steps to implement the executive order.

Furthermore, in the latter injunction, Talwani pointed out that the federal government failed to present literally any evidence of mail-in voting fraud:

Advertisement

The record is devoid of any declarations or other proffered evidence to suggest that mailin voting has resulted in voting by non-citizens.

In other words — the DOJ, despite the president insisting that non-citizen voting was happening all the time with mail-in ballots — didn’t even try to present evidence of that to the judge.

But this week, a USPS whistleblower revealed that the Postal Service has been building the machinery to implement the order anyway — issuing a final rule on August 26 and, per the disclosure, restarting development around July 29 even though the very clear injunction against doing anything was still in force. The whistleblower went to Senator Richard Blumenthal who released the whistleblower’s report, along with a letter to the Postmaster General demanding an explanation.

My office is in receipt of an alarming whistleblower disclosure (the “Disclosure”) outlining the United States Postal Service’s (“USPS”) perilously rushed and potentially unlawful implementation of President Trump’s Executive Order seeking to restrict mail-in voting. The whistleblower’s allegations make clear that USPS lacks the technical or operational capability needed to effectively implement the EO’s provisions in a way that safeguards every citizen’s right to vote in the upcoming midterm elections. Despite this, the Trump Administration appears intent on USPS moving forward with its flawed plans, no matter the chaos they may create. The whistleblower’s allegations also provide disturbing information suggesting that USPS may have violated a court order by continuing to implement the EO despite being ordered to cease all such work. We urge you to abandon this ill-conceived, unconscionable plan and ensure that all Americans can exercise their constitutional right to vote, including by mail, without interference by USPS.

The USPS’s defiance of the court order here is pretty direct. The judge issued an injunction on Section 3 of the executive order on June 25th. USPS did, in fact, stop work on the portal, while the DOJ appealed. On July 25th, the appeals court upheld the injunction, noting that the executive order “directs unprecedented levels of involvement by federal officials in how states administer elections.”

But just four days later, on July 29th, the whistleblower says that USPS leadership told the IT team to start building a tool to enforce the executive order, in direct and obvious defiance of the injunction against it. Then on August 11th, the district court expanded the injunction, which should have made it even clearer to USPS to stop. But USPS appears to have completely ignored that. While the Supreme Court put a stay on the injunction on August 24th, two days later the district court issued a temporary restraining order. But it appears that basically none of that mattered, as USPS leadership had the IT team continue to work on the thing they were explicitly barred by multiple courts to do.

Advertisement

As Blumenthal’s letter summarizes, the USPS rushed to build a portal whose main job appeared to be to block the mailing of mail-in ballots to voters (i.e., this is not them swiping already completed ballots, just refusing to send them to voters in the first place). And because USPS is now run by people whose main qualification is loyalty to Donald Trump, the execution is exactly as incompetent and slapdash as you’d expect:

The whistleblower’s Disclosure describes an unprecedented process that allows USPS to decide whether ballots issued by state election officials should be mailed. To do so, USPS is building an entirely new online system, the USPS Federal Ballot Mail Portal and related IT systems (the “Portal”), which will be used to screen ballots submitted by state election officials prior to USPS agreeing to mail them to voters. The Disclosure identifies problems at every stage of USPS’s development of the Portal, demonstrating deeply flawed plans for implementation. According to the whistleblower, USPS’s effort to develop and deploy the Portal has been “rushed,” “risky and haphazard” because leadership has demanded an impossible timeframe. In an effort to meet impossible deadlines, USPS has eliminated standard and needed testing, thereby creating substantial risk of a “catastrophic failure” of the system that could “derail the midterm elections.”

What could possibly go wrong:

USPS began work building the Portal on or around June 15, 2026 just three months before the date USPS planned to launch the system and just five months before the November 2026 midterm elections. On or about June 25, 2026, USPS ordered work on the Portal to cease due to a court order enjoining implementation of the EO. That work stoppage persisted for approximately a month, further reducing the time that USPS had to build the new system. According to the whistleblower, building the information technology infrastructure necessary to complete the Portal could take a year or more. Yet, USPS leadership demanded that the Portal be completed for a launch date of September 1, 2026, less than six months after the EO was issued. As a result of this rushed process, USPS has been unable to conduct tests of the Portal to ensure its proper functioning, troubleshoot problems, or distribute instructions on use to state election officials. According to the whistleblower, the Portal “violates standard principles of testing and debugging new software before launch.” Normal procedures at USPS for such systems include internal testing, customer acceptance testing, and a final development stage before release to public facing users. The Portal has gone through none of these basic checks.

Going beyond just Blumenthal’s summary, the actual whistleblower report has some astounding details about how the bosses at USPS working on this seem to have no clue how to build reliable software (one wonders if they’re ex-DOGE folks):

Throughout the development of the project, those giving guidance to tech developers lacked understanding of project parameters. Different team members continued to have different understandings of how the system is supposed to function which caused ongoing and greater confusion among the group.

While there continued to be no clear written requirements for the software and IT system, those developing the new election ballot mail IT system were placed in the position of trying to glean requirements from opaque comments at meetings. It continued to be clear that those giving directions did not understand exactly what was to be built. There was a growing concern that many were grasping at straws, trying to do their best to decipher cryptic instructions, and likely missing important details. Elements as basic to the project as whether a validation issue was a “warning” or an “error” continued to be unclear as leadership provided inaccurate information about these issues. To clarify, a warning allows a ballot to continue through the process while an error stops it. These occurrences reinforced the need for written requirements and the ongoing failures in communication.

Advertisement

Even so, the team was told that the system had to be ready to launch… by yesterday. They were given less than a month to figure it out. If you know anything about software development, project management, or… just about how anything works, these paragraphs are concerning:

Around this time at least one senior USPS official seemed to up the stakes by becoming a more active voice pushing for project completion on the new deadline. For example, when IT workers expressed concerns about the quality of the product under USPS leadership’s compressed timeline, the senior official stated that they (the official) “were not trying to stop anyone from getting their ballots and what is the problem?” Employees went on to reiterate concerns that many teams were still missing details of how systems were supposed to work and that written requirements could ensure that everyone was on the same page. The senior official was dismissive of these concerns. The conversation continued with others repeating the need for clear requirements; while leadership insisted that it was easy to understand what was needed and also that there was no time to write down the requirements. The contradiction was obvious that it should not take a great deal of time to write down something that is easily understood.

Concern continued to grow and the Whistleblower became aware that IT teams referred to the largely oral requirements as a “moving target.”

By the third week in August “user stories” – short, plain-language descriptions of a software feature written from the perspective of an end-user (focused on what a user wants to achieve and why) – were described as unusable “garbage”. User stories that had been generated had incorrect information and needed to be updated.

Throughout this project, the Whistleblower understood that IT teams were siloed and not communicating with one another. Teams had so little understanding what other teams were working on such that when elements were brought together, the teams were unaware of various developments, creating more work to utilize even the completed portions of the work.

Advertisement

By August 20, there was a massive rush as teams tried to get “everything committed” – in order to meet the goal of getting the ballot mail systems ready for customer testing on August 24. The resulting chaos caused work to be overwritten. By this point IT workers were resigned that even if they could get the portal put together and working in the internal development environment, there would not be enough time to test and fix any issue that would inevitably arise in customer testing.

The system was designated a grand total of four (FOUR!) days of user testing (and it’s not even clear if the testing actually happened):

By August 24 the expectation was that if somehow everything was accomplished on Monday the 24th, the code would end up in internal testing on Tuesday, August 25, then move to customer testing on Wednesday, August 26 allowing only four work days to test. For a system that manages something as important as handling voting and ballots, 4 days of user testing is entirely unreasonable. Only leadership seemed to express hope that the September 1 deadline was viable. If a problem was found during testing, which was almost certain, the IT workers would need to fix it and that fix would need to move back to internal testing and then into customer testing again. If a problem wasn’t found in the first 2 days, the fix could not make it back to the customer testing environment in time to meet the deadline.

In just the week prior to September 1, 2026, the Whistleblower learned that IT workers have described the election ballot mail development process as “a shit show.”

Very confidence building!

Advertisement

The whistleblower notes that a similar internal tech project that the USPS IT team built in the past “set aside 47 working days for testing.” And this one gets four.

Perhaps an even bigger problem than the slapdash hand-wavey “build a complex system in weeks with no written requirements, and no time for testing,” was the demand for a “zero percent failure rate.” That means that if a single barcode won’t scan — whether because of bad connectivity or a voter got married and changed their name — USPS bounces the entire batch back to the state. And these batches can run to tens of thousands of ballots. Back to Blumenthal’s summary:

Not only is this system astonishingly untested, USPS has simultaneously implemented an impracticable zero percent failure rate. When ballots are submitted to USPS in large-volume batches, if any one ballot in the batch cannot be verified against the Portal, all ballots in that batch will be rejected. For example, if a state election official brings a batch of 10,000 ballots to USPS and USPS is unable to match just one of those ballots against the Portal – because, for example, someone has recently changed their name after marriage or they’ve moved – then USPS would refuse to mail the remaining 9,999 ballots as well. As the whistleblower notes, “USPS expects the state to take back the entire batch to cure the issue with the single ballot…” Should the slapdash Portal mistakenly mark a ballot as unverified, there is no clear process by which state election officials or voters themselves can challenge the rejection. The Rule simply vaguely states that they “will be informed of the escalation procedures should they decide to challenge a rejection.” Voters intending to cast ballots by mail may not even be aware that their ballots have been rejected, or were part of a rejected batch, until it is too late to secure an alternative ballot or vote in person. Expecting a well-built, thoughtful Portal to return an accurate result 100 percent of the time is already a stretch—expecting a “rushed,” “risky and haphazard” Portal to do the same is a recipe for disaster.

A zero percent failure rate means that a single bad scan (which could happen for any reason) could block thousands of ballots (literally all of which could be legit and fine) from being sent out. Given that eight states already run elections entirely by mail, this could mean significant percentages of voters just not receiving their ballots at all.

And, we’re relying on a hastily built system with barely any testing not to have any bad scans that lead to thousands of ballots being blocked.

Advertisement

Of course, what Blumenthal and the whistleblower call “risky and haphazard” most others might call “deliberately designed to suppress votes and create chaos that will allow MAGA to call into question the validity of an election.”

Look, this is just terrifying: the president and his administration are building a system designed to guarantee that fewer people receive their ballots, in a manner designed to create obvious chaos around an election they don’t expect to win. Whatever you want to call the intent, that’s an executive branch actively degrading the machinery of free and fair elections.

That should be the biggest story in the country.

Donald Trump has made it abundantly clear that he thinks the federal government works for him, and him alone. It does not. It works for the American people, and a court has already told USPS exactly that, twice. One postal employee understood the assignment well enough to risk their job and blow the whistle over it. It’s about time that more started to do so as well.

Advertisement

Filed Under: david steiner, donald trump, election interference, elections, mail-in ballots, richard blumenthal, usps, voting, whistleblower

Source link

Advertisement
Continue Reading

Tech

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Published

on

Cyber computers

Infostealer logs have evolved from an underground commodity into an operational security problem. For defenders, finding an exposed credential is only the beginning. In today’s reality many security analysts start their morning with an alert: an employee’s corporate email address has appeared in a newly collected infostealer log. 

The log contains a username and password for a corporate SaaS application. There are browser cookies, meaning live sessions that can be exploited, and several other saved, in files, credentials. 

A personal employee computer got infected by Vidar located hundreds of miles from the company’s offices. Now what?

Resetting the exposed password seems obvious. But that may not solve the problem. If the stealer captured an authenticated session cookie, an attacker may already have a way into the application without needing the password or another MFA prompt. If the employee reused corporate credentials on a personal computer, the endpoint that created the exposure may not even be managed by the organization.

Advertisement

And somewhere in an underground Telegram channel, the same information may already be available to an initial access broker, ransomware affiliate, or opportunistic attacker.

This is the operational challenge security teams increasingly face with infostealer logs.

According to Flare Research’s Practitioner’s Guide to Monitoring Stealer Logs, approximately 46% of stealer logs containing corporate credentials originate from likely unmanaged or personal devices. Flare also estimates that exposure involving credentials and sessions for major productivity SaaS and cloud services is growing approximately 29% annually.

For defenders, the question is no longer simply whether they should monitor infostealer logs.

Advertisement

The harder question is: How do you separate a meaningless old password from an identity compromise that could be happening right now?

The needle among millions of needles

Infostealers such as RedLine, Lumma, Vidar and other malware families are designed to harvest information stored on infected systems.

Depending on the malware and configuration, that can include saved browser passwords, cookies, autofill information, cryptocurrency wallets, system information, VPN configurations and other authentication artifacts.

These are packaged to be sold under as an infostealer log, when a single infection can produce hundreds or thousands of individual records. Multiply that across a global malware ecosystem and defenders quickly encounter a scale problem.

Advertisement

While defenders need to process and validate everything, the attackers only need one valid valuable set of credentials. As Flare describes the problem, this isn’t finding a needle in a haystack. It is finding a specific needle among millions of needles in millions of haystacks.

While stealer logs historically circulated through underground forums and marketplaces, Flare’s research estimates that roughly 90% of logs now appear on Telegram, where public channels can advertise samples and private subscription channels can provide access to fresher datasets.

Infostealer logs can hand attackers a live, authenticated session that skips the password and MFA prompt entirely.

Flare monitors stealer logs across the dark web and Telegram in real time, so you can flag exposed corporate identities and sessions before they turn into account takeover.

Advertisement

Free 2-Week Trial

A password isn’t always the most dangerous thing in the log

With the vast amount of data in multiple channels, it’s hard to prioritize the risk level. If you work for a large corporate you are working with thousands of employees, if you start your day with two alerts, how can you establish what is riskier?

The first alert may involve employees’ old password for a consumer website appears in a six-month-old stealer log, whereas the second alert may have been collected yesterday and contains the employee’s corporate identity credentials and an authenticated browser session for the organization’s identity provider.

While both may be labeled as employee credential exposures, they are completely different.

This is why practitioners should prioritize monitoring around assets that tell them something about the potential impact, for instance corporate domains and subdomains, enterprise identity providers, session cookies, VPN and RDP endpoints, and cloud consoles.

Advertisement

Identity providers deserve particular attention, since a compromised SSO identity (Microsoft Entra ID, Okta, Google Cloud Identity, etc.) can open a path to multiple connected applications. Where possible, automated verification and mitigation further strengthen this protection.

The peril in session cookies

When a user successfully authenticates, an application can issue a session cookie, so they don’t have to authenticate with every request.

If malware steals that authenticated session, an attacker may potentially replay it.

So, if the attackers get ahold of a session cookie, and an infostealer collects them, they don’t necessarily need to log in. Stolen credentials alone still require authentication, creating an opportunity for defenders to detect or block the login, however, a valid session cookie may remove that step entirely. This effectively bypasses MFA.

Advertisement

The first 60 seconds

Flare recommends an initial assessment immediately after discovering potentially relevant stealer data, followed by risk scoring and validation.

The objective isn’t to conduct the entire incident investigation in the first few minutes. It is to determine how quickly the organization needs to react.

A useful first question is: What exactly was stolen? An analyst should determine when the infection occurred, what system produced the log, how many corporate credentials are present, and whether authenticated sessions were captured.

Then add business context.

Advertisement

A credential for testserver.company.com shouldn’t necessarily receive the same priority as one for finance.company.com.

Similarly, an exposed identity belonging to a marketing intern shouldn’t automatically be handled identically to an administrator with access to the identity provider, cloud console and production infrastructure.

The illustrative framework in Flare’s guide therefore places enterprise identity credentials combined with session cookies at critical severity, with a suggested response target of under one hour. VPN/RDP access combined with multiple corporate credentials is classified as high severity because of its lateral movement potential.

From exposure to investigation

Suppose our hypothetical employee’s log contains an Entra ID credential, corporate SaaS passwords and browser cookies, the next question is whether someone has already used them.

Advertisement

Defenders can correlate the exposed identity with authentication telemetry: successful and failed logins, unexpected geographies, unusual devices, unfamiliar IP addresses and access to resources outside the employee’s normal behavior.

They should also determine whether the stolen information is still usable. Has the password changed since the infection? Has the session expired? Is the account still active?

Flare’s recommended investigation workflow expands the analysis to include browser fingerprint information, the complete saved-credential inventory, information about the infected system, and additional artifacts such as VPN configurations or SSH keys.

Who is the employee? What can their identity access? Was the infected machine corporate or personal? Was this one infection or evidence of a broader campaign?

Advertisement

Authentication logs should then be examined across the systems accessible to that identity, prioritizing the most sensitive resources first.

Defenders should specifically look for behaviors indicating that exposure has progressed into account takeover: authentication from unexpected locations, access inconsistent with the user’s role, unusual downloads, password-reset activity, and enrollment of new MFA devices. This is how a stealer log becomes an early-warning sensor for identity compromise.

Treat stealer logs as an identity problem

Once a high-risk exposure is confirmed, speed matters. Defenders should invalidate compromised sessions, reset affected credentials, and increase monitoring around the identity.

Beyond individual incidents, organizations should track recurring exposures, affected applications, and whether stolen credentials lead to attempted access. 

Advertisement

Ultimately, infostealer monitoring has become an essential layer of identity security, enabling organizations to identify exposed credentials and sessions, understand the access they provide, determine whether they remain exploitable, and disrupt potential account takeover before it develops into a broader compromise.

Learn more by signing up for our free trial.

Sponsored and written by Flare.

Source link

Advertisement
Continue Reading

Tech

Apple, Google Pathetically Buckle To Trump’s Dim And Lazy Effort To Rename Lake Ontario

Published

on

from the ‘pathetic,-that’s-what-it-is’ dept

When we look back at this time and history words like “courage,” “integrity,” and “ethics” aren’t words you’re going to be associating with U.S. tech industry leadership. Everywhere you look you have tech sector executives either openly embracing fascism and the frontal assault on representative democracy, or too feckless and timid to take any sort of coherent stand on literally anything (and then wondering why the plebs are increasingly hostile to their software products).

Apple and Google’s quick decision to rename the Gulf Of Mexico at the behest of a mad and racist king was a lovely example; and now we’re back again with both companies quickly moving to rename Lake Ontario “Lake America” just because the increasingly unpopular U.S. President had a brain fart during his pointless and harmful trade war with Canada.

Google was the first to quickly make the change to appease Trump; in fact they acted so quickly on this the change to Google Maps happened before the government had even finished implementing it. Apple was very quick to follow suit, despite the fact that nobody at the company actually supports the ridiculous and pointless change:

These are, so we are clear, active choices — their mapping systems aren’t just innately and automatically following the lead of the authoritarian U.S. government’s GNIS data. Google (and the company’s defenders) had initially tried to insist they were following automated GNIS protocols, but that wasn’t actually the case:

Advertisement

“Google began rolling out this change for US users on Saturday. The company posted a brief update on its Google Maps blog, noting that it follows the US Geographic Names Information System (GNIS) for its maps, so the company implies it had no choice but to rename Lake Ontario in Google Maps, which is the most popular mapping platform in the US by a wide margin.

However, Google was even quicker to switch over to Lake America than the US government. While the GNIS database acknowledges the name change in a summary report, the base map layer still reflects the internationally recognized name of Lake Ontario. A message across the top of the USGS-operated website notes that the change to official maps is still pending.”

Even then, there’s nothing saying Google couldn’t have ignored the GNIS changes for the sake of product quality. As it is, both Apple and Google are still ensuring that U.S. users of both mapping products see King Trump’s pointless change, while everybody else in the world sees material reality.

This lightning-fast choice to quickly buckle to the incoherent whims of a tyrant over something this stupid certainly raises questions about what kinds of subservience we don’t know about yet by these titans of U.S. innovation. There was some hope that Apple, with new CEO leadership and no shortage of “fuck you money,” would demonstrate some sort of ethical leadership here, but alas.

Amusingly Mapquest (and I guess TomTom) used Apple and Google’s abject fecklessness to market “having the slightest hint of a backbone” as a market branding differentiator:

Advertisement

“The company said its mobile app received hundreds of thousands of downloads after it announced Thursday that the name Lake Ontario would remain on its apps, despite Trump directing the Interior Department to update the lake’s name in the Geographic Names Information System (GNIS).”

This is still somehow occurring despite the fact that Trump’s support is cratering due to pointless wars, high oil prices, sagging polling, and clearly waning health. Even on these peripheral issues where taking a stand could be easily defended by an ocean of highly paid lawyers, executives can’t even muster the vaguest outline of some sort of meaningful backbone.

I’m sure they’d argue that it’s their fiduciary responsibility to shareholders to not “antagonize” the U.S. government. But where’s the fiduciary responsibility to the continued existence to functional markets, industry autonomy, and democracy in a country under assault by some of the dimmest, most incompetent and corrupt autocrats the American experiment has ever seen?

Filed Under: apple maps, authoritarians, big tech, cowardice, donald trump, fascism, google maps, lake america, lake ontario

Companies: apple, google, mapquest

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025